• Squid3 whitelist

    3
    0 Votes
    3 Posts
    909 Views
    A

    Thanks for the suggestion.  I'll try it in a few hours.

  • Squid3 with pfsense 2.2.4

    4
    0 Votes
    4 Posts
    1k Views
    KOMK

    Is there an error message of some kind or does it simply time out?  Anything in /var/logs/squid/access.log?  Have you restarted the server after installing squid?  After installing, did you change any settings besides checking the Transparent mode?  Btw, transparent mode will not work with HTTPS unless you install a certificate on every client computer.  Look into configuring WPAD auto-detection instead.

  • HTTP requests fail after upgrade to 2.2.4

    4
    0 Votes
    4 Posts
    727 Views
    KOMK

    squidGuard isn't really a service.  It's an application that gets called by squid for every URL that squid processes, so the service status thingy for squidGuard is useless.

  • Squid and Squid 3

    2
    0 Votes
    2 Posts
    942 Views
    KOMK

    After you install squid, you need to either reboot the server or restart the squid service.  It seems to block all web access until you bounce it.

  • How to give access to a user to view realtime of squid3

    5
    0 Votes
    5 Posts
    1k Views
    A

    I can't thank enough…. you guys are too prompt. Thanks to BBCan and doktornotor for the pointer.

    This is what I did :-    copied the file to /etc/inc/priv/squid3.priv.inc.

    Gave access rights  to webcfg:squid3 to user manager

    It worked :)

    A special thanks to doktornotor as he comes to rescue whenever I am struck.

    with warm regards,
    Ashima

  • 0 Votes
    1 Posts
    974 Views
    No one has replied
  • Squid3 Antivirus on 2.2 release

    6
    0 Votes
    6 Posts
    5k Views
    D

    This nonsense is fixed properly as a part of https://github.com/pfsense/pfsense-packages/pull/1080 (specifically this commit).

    Couldn't work since it was trying to patch a file that's actually not distributed  ::) Why's the LDAP part being patched fails my understanding as well, the line is commented out in the first place.

  • ASCII codes SquidGuard integrated with AD

    1
    0 Votes
    1 Posts
    564 Views
    No one has replied
  • SquidGuard, no such file or directory, emergency mode

    8
    0 Votes
    8 Posts
    4k Views
    KOMK

    Replacing domain with ip would have also fixed it.

  • Configuring Multi WAN setup with proxy wpad

    4
    0 Votes
    4 Posts
    1k Views
    C

    @Abhishek:

    Ok, so what is the possible way to deploy squid in multi wan environment

    Just deploy Squid on another server, not pfSense  ;)

  • HAProxy RDP load balancing

    2
    0 Votes
    2 Posts
    3k Views
    P

    Hi Dennes,

    I have not tried to loadbalance RDP.. But here some of my thoughts about the subject.

    For haproxy you should only use "Transparent ClientIP" (tproxy) if you absolutely need the client ip on the backend servers for a known purpose. The RDP-TCP connection itself wont need it. And it wont help in getting the same client connect to the same server every time..

    'Balance Source' would probably work good assuming all servers stay up.. And might have 10 users on server A while 50 users are connected to server B. And even a newly connecting user could be added on server B depending on how the hash ends up..

    'Least Connections' could be another option to use, together with "Stick-table persistence" on 'source ip', though you will have to think about how long a source-ip is 'remembered'..

    You could also try the build-in loadbalancer, and compare if there is any performance difference between the two.?. Though i think you will find it has to few options to accompany the desired stickyness.

    My two cents..
    PiBa-NL

  • Squid 3 doesn't update configuration

    6
    0 Votes
    6 Posts
    1k Views
    G

    OK, it works!
    Thank you doktornotor.

  • Squid ssl https cache pdf files

    25
    0 Votes
    25 Posts
    5k Views
    S

    @JStyleTech:

    Possibility #1 - If your caching currently works and your SSL is setup correctly, there might just be a limitation with the "Maximum object size" under the "Local Cache" Tab of Squid.  If you want to cache a 100Mb file this setting should be at least "100000" as it represents kilobytes.  I currently have mine set to 300000.

    richie1985 allready post his squid.conf
    and "maximum_object_size" is set to  512000 KB

    @JStyleTech:

    Possibility #2 - perhaps you have an proxy exception rule applied to either an IP address or URL which could be linked to a hosted CDN.  If you don't use any proxy exception rules then you can ignore this, but
    if you do you might try disabling the rule temporarily and simply retest.

    I've personally setup two Aliases for this specific reason "Proxy_Bypass_Hosts" and "Proxy_Bypass_Ranges".  I use these specifically to whitelist sites, IP's and/or IP Ranges using ARIN and Robtex when addressing problem applications or services.

    Cand find anything that point to an exeption in the squid.conf

  • Release of Squid 3.5 ?

    7
    0 Votes
    7 Posts
    1k Views
    A

    @azharkov:

    @doktornotor:

    Not until pfSense 2.3 is out, for sure.

    Check
    https://forum.pfsense.org/index.php?topic=99141.msg556045#msg556045

    Hey thanks bro  ;D

  • [ask] forward to external proxy

    2
    0 Votes
    2 Posts
    695 Views
    S

    well this thread also have same issue like me

    https://forum.pfsense.org/index.php?topic=87493.msg480628#msg480628

  • Problem with web filtering

    8
    0 Votes
    8 Posts
    1k Views
    M

    WPAD would probably be the way to go. I've just spend some time configuring it on my network. You might have to manually configure mobile devices. Android doesn't appear to be too user friendly just yet with wpad.  You might be able to specify a personal acl that points to a list of sites you want blocked. I don't know how exactly to implement this with pfsense.  Generally squid has a .conf file where you can specify this but I am not seeing one here.

  • How to configure ssl offloading with haproxy and pfsense

    3
    0 Votes
    3 Posts
    3k Views
    K

    thanks PiBa-NL for your reply and suggestions.

  • PfSense 2.2.3 - Internet is very slow via Squid3

    32
    0 Votes
    32 Posts
    21k Views
    A

    Ok some logs

    When I stop and start squid I get

    Sep 22 10:27:31 squid[22754]: Squid Parent: (squid-1) process 23039 started Sep 22 10:27:31 squid[22754]: Squid Parent: will start 1 kids Sep 22 10:27:22 php-fpm[84775]: /status_services.php: The command '/usr/local/etc/rc.d/squid.sh stop' returned exit code '1', the output was '2015/09/22 10:27:17| Warning: empty ACL: acl throttle_exts urlpath_regex -i "/var/squid/acl/throttle_exts.acl" squid: No running copy' Sep 22 10:26:48 php-fpm[67812]: /status_services.php: The command '/usr/local/etc/rc.d/squid.sh stop' returned exit code '1', the output was '2015/09/22 10:26:42| Warning: empty ACL: acl throttle_exts urlpath_regex -i "/var/squid/acl/throttle_exts.acl"

    In squid real time if I do squidclient -h 192.168.1.1 -p 3128 mgr:info
    I get

    22.09.2015 10:33:03 192.168.1.244 TCP_DENIED/403 127.0.0.1:59243 - - 22.09.2015 10:32:12 192.168.1.244 TCP_DENIED/403 127.0.0.1:59243 - - 22.09.2015 10:32:01 192.168.1.1 TCP_MISS/403 cache_object://192.168.1.1/info - 192.168.1.1 22.09.2015 10:31:46 192.168.1.1 TCP_MISS/403 cache_object://192.168.1.1/info - 192.168.1.1 22.09.2015 10:31:43 192.168.1.1 TCP_MISS/403 cache_object://192.168.1.1/info - 192.168.1.1 22.09.2015 10:31:40 192.168.1.1 TCP_MISS/403 cache_object://192.168.1.1/info - 192.168.1.1 22.09.2015 10:31:22 192.168.1.1 TCP_MISS/403 cache_object://192.168.1.1/info - 192.168.1.1 22.09.2015 10:29:59 192.168.1.244 TCP_DENIED/403 127.0.0.1:59243 - - 22.09.2015 10:26:28 192.168.1.244 TCP_DENIED/403 127.0.0.1:59243 - -
  • Squid Whitelist (cache only)

    2
    0 Votes
    2 Posts
    788 Views
    KOMK

    I don't understand the problem.  If you don't care about URL filtering, why do you care about what is sitting in the cache?

  • Squid3 Rev.Proxy 'wan' <-> DMZ ? How to disable NAT ?

    1
    0 Votes
    1 Posts
    581 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.